CVE-2006-6811 describes a denial-of-service vulnerability in KsIRC 1.3.12, affecting various distributions including Canonical Ubuntu Linux and KDE KsIRC. A remote attacker can crash the application by sending a specially crafted, long PRIVMSG string when connecting to an IRC server, leading to an assertion failure and NULL pointer dereference. This vulnerability has a CVSS v3.1 score of 6.5 (Medium), indicating it can be exploited over the network with low complexity, requiring user interaction, and resulting in high availability impact. While not actively exploited in the wild and lacking Metasploit or Nuclei modules, a Proof-of-Concept exploit is available on ExploitDB, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.3.12CPE matchmatch criteria | cpe:2.3:a:kde:ksirc:1.3.12:*:*:*:*:*:*:* | ||
5.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:5.10:*:*:*:*:*:*:* | ||
6.06CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:* | ||
6.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:6.10:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.